Contact OWASP London Chapter for event and ticket information.

This event has ended!

View current events hosted by OWASP London Chapter

OWASP London - March 2012 Chapter Meeting

Thursday, March 29, 2012 from 6:30 PM to 8:30 PM (GMT)

London, United Kingdom

OWASP London - March 2012 Chapter Meeting

Ticket Information

Type End     Quantity
RSVP Ended Free  
Share this!

Event Details

Talks

  • Deep Access Control Best Practices and Anti-Patterns - Jim Manico
    Access Control is a necessary security control at almost every layer within a web application. This talk will discuss several of the key access control anti-patterns commonly found during website security audits. These access control anti-patterns include hard-coded security policies, lack of horizontal access control, and "fail open" access control mechanisms. In reviewing these and other access control problems, we will discuss and design a positive access control mechanism that is data contextual, activity based, configurable, flexible, and deny-by-default - among other positive design attributes that make up a robust web-based access-control mechanism.
  • IronWASP - Manish Saindane
    IronWASP (Iron Web application Advanced Security testing Platform) is an open source system for web application vulnerability testing. It is designed to be customizable to the extent where users can create their own custom security scanners using it. Though an advanced user with Python/Ruby scripting expertise would be able to make full use of the platform, a lot of the tool's features are simple enough to be used by absolute beginners.

Speakers

  • Jim Manico is the VP of Security Architecture for WhiteHat Security, a web security firm. Jim is a participant and project manager of the OWASP Developer Cheatsheet series. He is also the producer and host of the OWASP Podcast Series.
  • Manish Saindane is a Senior Security Consultant at Gotham Digital Science. He also co-authors a security research website and bloghttp://andlabs.org. He has actively contributed towards conceptualising IronWASP and also maintains the Ruby plug-in repository for this framework.